← All COMPTIA Flashcard Decks

ITF+ Information Security Principles Flashcards

7 cards from real COMPTIA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 ITF+ Information Security Principles flashcards as text
  1. A user receives an email claiming their bank account will be suspended unless they click a link and verify their credentials. What type of attack is this?

    Answer: Phishing

    Phishing uses deceptive emails that impersonate trusted entities to trick users into revealing credentials.

  2. Which of the following BEST describes the principle of least privilege?

    Answer: Users should only have the minimum access rights needed to perform their job

    Least privilege limits user access rights to only what is necessary, reducing the attack surface.

  3. What is the purpose of multi-factor authentication (MFA)?

    Answer: To require verification from two or more different categories of credentials

    MFA requires proof from at least two categories: something you know, have, or are — making unauthorized access much harder.

  4. A company stores customer credit card numbers in plain text in a database. Which security control is MOST needed?

    Answer: Encryption

    Encryption converts sensitive data into an unreadable format, protecting it even if the database is compromised.

  5. Which of the following is an example of 'something you are' in authentication?

    Answer: Fingerprint scan

    Biometrics like fingerprints represent 'something you are' — a physical or behavioral characteristic unique to the user.

  6. What does a VPN primarily provide for remote workers?

    Answer: A secure, encrypted tunnel over a public network

    A VPN creates an encrypted tunnel that protects data as it travels across untrusted networks like the internet.

  7. An attacker intercepts and alters communication between two parties without their knowledge. What type of attack is this?

    Answer: Man-in-the-middle

    A man-in-the-middle attack secretly intercepts and potentially alters communications between two parties.